Email and web monitoring laws 'to be brought in soon' [UK]
bbc.co.uk
bbc.co.uk
I find myself thinking "I don't want to live on this planet anymore" more and more often these days. Not sure if I'm just getting older, or the world really is going to shit.
Sorry the total is 4,384. For some reason the site only shows you the latest number after signing.
(Edit: Correcting previous assertion.)
I'm a thick idiot and I can work that out, so presumably the government can too.
This is not about terror and all that scare story stuff, its population surveillance.
Some how these governments need reminding that we the people are supposed to be the boss. They serve us, not the other other way round.
I'm giving advice in private messages about how to use Truecrypt (especially when using Dropbox or any remote backup or cloud sync service), what a VPN is and how to use Relakks or IPredator, etc.
Just basic things, yet the reaction has been extremely positive. One of the sites I run exists by donations, and just for giving this advice 1 person donated £100 to the running of the site because in his words "No-one else is telling me to encrypt or helping me.".
The big glaring omission in all of this is email. We all want a secure email system, and one that doesn't involve locking yourself into a single provider (Hushmail), and yet can co-exist with sending email to recipients on webmail and corporate solutions.
Talk about a big hole in the market.
I've not pitched this to my users as "here's how to pirate", it's just been "privacy is core to democracy, encryption protects your privacy". And additionally I've argued to them that if they were amongst the people who turned their Twitter avatars green last year for Iran, then by not using encryption they leave encryption to "terrorists, criminals and dissidents", who cares for the first two, but if you care for the last you'll encrypt too to ensure that their dissenting opinion can be voiced safely in private.
I got the idea for telling my users all of this from HN, and specifically a link to a Canadian site:
http://encrypteverything.ca/index.php/Main_Page
Then I also shared links to:
https://www.eff.org/https-everywhere
https://www.relakks.com/?lang=eng
https://ssd.eff.org/tech/encryption
I truly think that the best response that the people of Britain can give to these proposals is to encrypt everything and take away from the government the ability to pervasively spy on their own populace like this.
With most governments and corps it always feels like that ask for a mile, and when we object they concede half a mile. We're happy, but then they do this a few times and they get to where they wanted to be.
What better way to halt this for good than to encrypt everything.
Now, if someone could just give us email v2, secure by default. I'd happily pay for it. Just make it work, and make it open source and aim for it to be standard... don't give me another closed service to achieve it.
Does any of this really stop the snooping, or is it just giving a false sense of security?
Then, would deploying all this on a day to day basis suggest to a paranoid snooper that one is hiding something than there for a legitimate target for more snooping?
1) It anonymises where the traffic originated ( in the case of a VPN run along the lines of Relakks )
2) It encrypts, so whilst if you weren't using a VPN they'd still see traffic go from point A to point B, they wouldn't have a record of the contents of the communication
Neither of those things is a false sense of security.
And yes to the last... if only those who feel that they have something to hide encrypt things, then you might reasonably expect a person who is suspicious of others to reach that conclusion.
But I would argue that everyone has something to hide. Privacy isn't just core to democracy and free speech, it's core to intimacy too.
So you end up with two strong arguments to encrypt, one is to protect your own privacy, and then from your argument about how only "those with something to hide, encrypt", comes the second which is that most freedoms enjoyed by people were earned through dissent and revolution (and war, but that doesn't help this particular argument)... are such things possible in a society that pervasively spies in it's own citizens?
So to protect the future dissidents you should in addition to caring for your own privacy, encrypt to ensure you give protection to those who may one day be fighting for your rights.
PGP (and it's mathematical foundations to some degree) were invented to solve the secure email problem. Back then the proponents of PGP essentially predicted the situation we're in now. Up until now there's been plausible deniability for any of us normal people to care, so consumer adoption of PGP remains close to nil. Even corporate use I've seen only comes into play when dealing with another company who forces it be used.
That's changing fast. Their original use case (secure messaging in a monitored society) is no longer only a tinfoil hat situation.
The solution is for all of us HNers to adopt PGP 100%. Everyone who wants to talk to use would have to adopt PGP. The friction to start is rather huge but that is how something like this would get adopted.
As for "but it doesn't jive with my gmail nicely".. maybe it's time we give up gmail too. It's value proposition is based on reading your email to be better build a profile on you to sell to advertisers. That's why google plus wanted your real name, so they have a face to put all that mined data to.
Switch To PGP Day?
edit: relevant links
"simple pgp chrome plugin for gmail" - http://news.ycombinator.com/item?id=2918255
Hushmail comply with correctly formed legal requests (they have to) but they go as far as creating back-doored java apps and serving them to specified customers. I guess it's harder for English LEOs to get correct legal documents to an American company for English customers. But I don't know.
The cynic in me says it's been done in this way on purpose, i mean, don't want to make the feds actually do any work to be able to snoop around my emails.
The proposed legislation will apparently still require a warrant for the contents (and in the UK you will be required to decrypt the contents on demand).
So while I agree that PGP is a good thing, it will not work around this proposed legislation at all.
If I had to choose, I would prefer to see effort going into political action to prevent this law being passed instead. This is an unwarranted privacy intrusion by definition. If it were warranted, then the police would be able to get a warrant.
Because the monitoring is out of site, and cheap in terms of man power, now it's allowed.
I really find it amazing.
The idea that communications can be monitored with oversight is not a new one. Law enforcement departments have been able to tap phones with a warrant for decades.
Edit: Hm, the article is actually a little unclear on whether or not a warrant is needed. At the top it says it is, and then in the middle it quotes a bunch of people saying it isn't...
I think previously they could only start monitoring after a court order had been granted (same as listening in on your phone calls) whereas now they record everything and (presume) would have historical access once the court order had been granted...
However, the home secretary told the Sun that "ordinary people" would have nothing to fear from the government's plans.
I think those 2 quotes sum it up really. And they say the Arab nations are oppressive... I can't believe the kind of morons we have running this country for us, but certainly explains when we're in such a financial sh!t.
http://thenews.pl/1/9/Artykul/95154,Poles-still-under-watchf...
All round, rather depressing.
A nearly-identical law, the Recording and Interception of Communications Act (RICA), was enacted in 2002 in South Africa. While in theory it contained all the legal protections that have been proposed for the UK legislation, in practice it has been badly abused.
Between 2006 and 2010 just one of the South African government's regional interception centres (of which there are at least four and potentially many more) carried out over 3 million legal interceptions, a number which is known to have increased since then. Subsequent leaks to the media have revealed that even this is a drop in the ocean; illegal interceptions are performed routinely and are easily hidden from oversight amongst the millions of legal interceptions performed every year.
Looking at the numbers involved, it's not unreasonable to assume that every single connected South African will have their communications intercepted at some point, sometimes in illegal interceptions with no official control over the data collected. In fact, there have been examples of staff inside the interception centres being bribed by business rivals, spouses and others to spy on innocent citizens.
I see no reason why the UK will be immune to these types of abuses, despite having a less corruptible civil service. This kind of power in the hands of poorly-monitored government intelligence agencies is always a bad idea.
And GCHQ already have access to this data, the new law just makes access 'real time' rather than retrospective.
I don't have much of a problem with GCHQ using it... but the Department for Work and Pensions? Also, a lack of warrants is concerning.
It feels very much like a law that could be exploited by anyone.
It's right there in the bit you quoted:
> the Department for Work and Pensions, should have to apply to a court before access was granted
Allowing the DWP to have access to anything without a warrant would be bad. Allowing them to have access to destination / address data with a warrant might be okay. Allowing them to have access to content data is probably a bad thing. I think I'd prefer Serious Organised Crime Agency to all of it; and I'd prefer some better oversight. Whether that's a warrant (good) or a chief inspector of another force (bad) remains to be seen.
Don't forget that this is, essentially, just an extension to things like RIPA (Regulation of Investigatory Powers Act) to cover new forms of communication.
I agree that we need to be careful that they don't kludge in things like "looking at the content is fine" or "you don't need warrants".
It would compel UK based startups to keep a log of all this data, which of course costs time an money, reducing the UK's competitiveness.
Ask anyone who has ever worked on infrastructure at a large UK ISP or exchange (e.g. LINX). Copious secret services systems are already used.
The key difference, the key burden that is being (publicly) demanded in 2012 by the services is real-time! Presumably, this was such a burden to the overall infrastructure of the majority of UK ISPs that they just pushed back when requested... hence the new law proposals.
Go on...